The primary safeguard for protecting information held in CRIS, CRISSP and L17 involves revoking user access when employees cease working in a relevant role at a funded organisation. Complying with user management procedures is a contractual requirement under the Agreement for the access to and use of information on the CRIS and CRISSP systems (‘the Agreement’).
Under the Agreement, funded organisations must appoint an Organisation Authority (OA) who is responsible for keeping CRIS, CRISSP and L17 access permissions up to date and ensuring that people only have access where it is essential for their work.
The last CRIS and CRISSP user access audit was completed in March 2026. The L17 user access audit is being completed for the first time, in collaboration with the CRIS and CRISSP audit program.
If you have questions about the CRIS and CRISSP audit program, e-mail ClientInformationSystems.Audit@dffh.vic.gov.au
If you have questions about the L17 audit program, e-mail L17portal@dffh.vic.gov.au
Any questions about Privacy can be directed to your Agency Performance and System Support (APSS) Adviser.